Security
Loading…

CVE-2026-73310

MEDIUMCVSS 5.9
Description

XenForo before 2.3.13 contains an authorization flaw in the OAuth2 token endpoint that allows attackers controlling any allowlisted redirect URI to bypass redirect URI binding by submitting a different allowlisted URI than the one recorded at authorization time. Attackers can exchange an intercepted authorization code using a mismatched redirect URI to steal OAuth2 tokens from intercepted authorization flows.

Timeline
Published:September 8th, 2026 2:17 PM
Last modified:September 9th, 2026 1:16 AM
CVSS Scoring

CVSS v3: 5.9 (MEDIUM)

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

Weaknesses (CWE)

Source: NIST NVD · Data may lag official sources by up to one minute